The Rule That Missed Its Own Reason for Existing
Dipina Paul
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
In July 2026, two OpenAI models breached test area and spent days inside Hugging Face's real systems. Two days later, US Congress passed a new bill to stop such incidents. The bill is called the AI Kill Switch Act. But the bill exempts such incidents occurring during safety tests. So, the bill would not have covered the incident that led to it. This report identifies that gap and crosschecks it against the bill's own text. This report also does a comparison of how similar incidents are being handled at three other places: the EU, California, and New York. Along with having a real deadline for reporting an AI incident, all three of them doesnot provide similar exemption as the US bill. This report thus recommends, specific fix to the bill's wording, and also suggests similar amendments to a second US bill, H.R. 9477, before its enactment.

Reviews
I appreciate the author's analysis of existing regulations and whether they adequately capture the infamous HF incident. I had a bit of trouble understanding the methodology, and I don't think it's fair to say in the conclusion that any kill switch act has been "passed."
The paper would benefit from more rigorous legal analysis grounded in the primary legislative texts, particularly on how each jurisdiction treats incidents that occur during testing.
Cite this project
@misc{paul2026rule,
title = {{The Rule That Missed Its Own Reason for Existing}},
author = {Dipina Paul},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/the-rule-that-missed-its-own-reason-for-existing-21vd}},
url = {https://apartresearch.com/sprints/projects/the-rule-that-missed-its-own-reason-for-existing-21vd}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …